⤷ Title: Kafka Authentication Bypass in the OAUTHBEARER JWT Path
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 10 Jul 2026 12:01:48 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Kafka #Authentication Bypass #JWT #OAUTHBEARER #oss_security #SASL
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 10 Jul 2026 12:01:48 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Kafka #Authentication Bypass #JWT #OAUTHBEARER #oss_security #SASL
Daily CyberSecurity
Kafka Authentication Bypass in the OAUTHBEARER JWT Path
TL;DR A researcher disclosed a Kafka authentication bypass in the OAUTHBEARER login path. It affects Apache Kafka 4.0.0 through 4.0.x. An attacker can replay a captured JWT long after it expires. …